Back to trending CVEs

Week of September 21, 2026

Trending* CVEs over the last 7 days (from September 14, 2026 to September 21, 2026)

1
CVE-2026-76460Cisco Systems / Cisco Identity Services Engine
NewKEV
SYRN Score92
CVSS10.0
Activity105
Published09/16/2026
StatusHighly Active

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

2
CVE-2026-76461Cisco Systems / Asyncos
NewKEV
SYRN Score93
CVSS9.8
Activity101
Published09/14/2026
StatusHighly Active

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

3
CVE-2026-58704Google / Android
NewKEV
SYRN Score80
CVSS8.0
Activity70
Published09/15/2026
StatusHighly Active

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

4
CVE-2026-85706Gitlab / Gitlab
KEV
SYRN Score96
CVSS10.0
Activity49
Published09/12/2026
StatusHighly Active

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

5
CVE-2026-91843Checkpoint / Quantum Security Management
New
SYRN Score67
CVSS9.8
Activity48
Published09/16/2026
StatusHighly Active

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

6
CVE-2026-87886Acronis / Acronis Backup
NewKEV
SYRN Score80
CVSS7.8
Activity35
Published09/17/2026
StatusHighly Active

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.

7
CVE-2026-58138Netflix / Conductor
SYRN Score92
CVSS9.3
Activity24
Published06/30/2026
StatusActive

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.

8
CVE-2026-53266Linux / Linux Kernel
KEV
SYRN Score86
CVSS8.8
Activity24
Published06/25/2026
StatusActive

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits().

9
CVE-2025-39964Linux / Linux Kernel
KEV
SYRN Score80
CVSS7.8
Activity23
Published10/13/2025
StatusActive

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

10
CVE-2026-41940Cpanel / Cpanel
KEVRansomware
SYRN Score99
CVSS9.3
Activity22
Published04/29/2026
StatusActive

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

* Trending is based on the number of sightings collected from SYRN's threat intelligence sources over the given period.

Monitor these vulnerabilities and get alerted when new threats target your stack.

Get Started Free